Privacy Policy
2.1Introduction
This Privacy Policy explains how Raseen Technology Labs Ltd (“Raseen Labs”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data in connection with the Raasel software (“Software” or “Raasel”) and the Raseen Labs website at raseenlabs.com (the “Website”).
This Privacy Policy is aligned with the DIFC Data Protection Law 2020 (DIFC Law No. 5 of 2020) and accompanying regulations.
If you have questions or concerns about this Privacy Policy, contact us at dataprotection@raseenlabs.com. Raseen Labs has not appointed a formal Data Protection Officer under DIFC DPL Article 16; see §2.16 for the basis.
2.2Scope and Applicability — Important: Self-Hosted Software Model
This Privacy Policy describes how Raseen Labs processes personal data that Raseen Labs collects directly. It does not govern personal data that flows through Customer deployments of the Software.
Raasel is software that customers deploy and operate on their own infrastructure (“Customer Infrastructure”). Under this self-hosted deployment model:
- Customer Data — the content of communications transmitted through Customer's deployment, including messages, files, user accounts, and metadata — is stored on Customer Infrastructure. Raseen Labs does not host, access, or process Customer Data.
- End Users (individuals using a Customer's Raasel deployment) interact with Customer's infrastructure, not with Raseen Labs.
- The Customer is the data controller for Customer Data. The Customer's own privacy policy, not this one, governs how Customer Data is processed within Customer's deployment.
Raseen Labs's direct relationships are with:
- Website visitors to raseenlabs.com (including legal page readers, blog readers, etc.)
- Customers who download, license, or receive support for the Software
- Software installations that send optional, opt-in telemetry or crash reports back to Raseen Labs
This Privacy Policy applies to those direct relationships only.
2.3Data Controller
The data controller responsible for the personal data described in this Privacy Policy is:
Raseen Technology Labs Ltd
Premises IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates
DIFC registration number: CL12279
Email: dataprotection@raseenlabs.com
2.4Information We Collect
2.4.1Information you provide directly to us
We collect personal data you provide to us when you:
- visit the Website and interact with forms (contact us, request a demo, subscribe to updates);
- create an account for the Raseen Labs developer portal or licensing system, if applicable;
- communicate with us by email, support ticket, or other channels;
- attend events, webinars, or programs organized by Raseen Labs;
- apply for employment with Raseen Labs.
Typical categories of personal data we collect directly include: name, email address, organization name, job title, country of operation, communications content, and account credentials (hashed).
2.4.2Information collected automatically
When you visit the Website, we may automatically collect:
- Device and browser information — user agent, IP address, screen resolution, language preference, time zone.
- Usage information — pages visited, time spent on pages, referring URL, click-through paths.
- Cookies and similar technologies — see §2.12.
2.4.3Information from the Software (opt-in only)
The Software may, with Customer's explicit opt-in, transmit limited data to Raseen Labs for the purposes of:
- Update checking — version information of the running Software, to inform the Customer about available updates.
- Crash reports — anonymized stack traces and runtime context when the Software crashes, to help Raseen Labs improve quality.
- Aggregated, anonymized usage telemetry — feature usage counts and performance metrics, without personally identifying information.
These transmissions are opt-in and can be disabled at any time in the Software's settings. Without explicit opt-in, the Software does not transmit any data to Raseen Labs.
2.4.4Information from third parties
We may receive personal data about you from third parties, including:
- our authorized partners and resellers;
- public sources (e.g., business registries) for due diligence purposes;
- background-check providers, when evaluating job applicants.
2.5Purposes and Legal Bases for Processing
We process personal data for the purposes set out below. Under DIFC DPL Article 10, each processing purpose must have a lawful basis. The bases we rely on are:
| Purpose | Legal basis under DIFC DPL |
|---|---|
| Responding to your inquiries and providing information you requested | Consent (Art. 10(1)(a)) or Legitimate Interest (Art. 10(1)(f)) |
| Providing the Software and any associated support | Performance of a contract (Art. 10(1)(b)) |
| Managing customer accounts and license registrations | Performance of a contract (Art. 10(1)(b)) |
| Sending marketing communications about Raseen Labs products | Consent (Art. 10(1)(a)) |
| Analyzing Website usage to improve our services | Legitimate Interest (Art. 10(1)(f)) |
| Processing crash reports and opt-in telemetry from the Software | Consent (Art. 10(1)(a)) |
| Complying with legal and regulatory obligations | Legal obligation (Art. 10(1)(c)) |
| Defending against legal claims | Legitimate Interest (Art. 10(1)(f)) |
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
2.6How We Use Personal Data
We use the personal data we collect to:
- communicate with you about the Software, support requests, and account matters;
- provide, maintain, and improve the Software and Website;
- send marketing communications you have opted in to receive;
- analyze Website and Software usage trends in aggregate;
- detect, prevent, and respond to security incidents and abuse;
- comply with legal obligations, including responding to lawful requests from regulators;
- enforce our Terms of Service and Acceptable Use Policy;
- exercise or defend legal claims.
We do not use Customer Data (the content of communications transmitted through Customer deployments) for any purpose, because we do not have access to Customer Data under the self-hosted model.
2.8Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements.
| Data category | Retention period |
|---|---|
| Customer account and licensing records | Duration of license + 5 years (covers UAE Federal Tax Authority record-retention requirements and dispute statute of limitations) |
| Support tickets and related communications | 3 years |
| Marketing contact records (where you have not opted out) | Until opt-out, or 2 years after last engagement, whichever is sooner |
| Website analytics (aggregated) | 14 months |
| Crash reports and opt-in telemetry | 180 days |
| Employment applicant records | 12 months (if not hired) |
When personal data is no longer needed, we securely delete or anonymize it.
2.9Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- encryption of personal data in transit (TLS) and at rest where appropriate;
- access controls and authentication for systems holding personal data;
- regular security assessments and vulnerability management;
- staff training on data protection and security;
- contractual safeguards with service providers handling personal data;
- incident response procedures for security breaches.
No security measure is perfect. While we strive to protect personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the DIFC Commissioner of Data Protection in accordance with DIFC DPL Articles 41–42.
2.10International Data Transfers
Raseen Labs is based in the DIFC. We may transfer personal data outside the DIFC for processing by our service providers in other jurisdictions. When we do so, we ensure appropriate safeguards in accordance with DIFC DPL Articles 26–28, including:
- transfers to jurisdictions recognized by the DIFC Commissioner as providing adequate protection;
- standard contractual clauses approved by the DIFC Commissioner;
- binding corporate rules for intra-group transfers;
- specific derogations where applicable (e.g., consent, contract performance).
Personal data may be transferred to the following jurisdictions, with safeguards aligned with DIFC DPL Articles 26 and 27 as declared in the Article 14 notification filed with the DIFC Commissioner:
Jurisdictions recognized by the DIFC Commissioner as providing adequate protection (Article 26 transfers):
- California, United States — Microsoft Corporation, GitHub, Stripe, Zoho Corporation (CCPA-subject)
- Ireland — Microsoft Ireland Operations Limited
- Germany — Hetzner Online GmbH (cloud hosting)
- United Kingdom — UK-based vendors and advisors
- Abu Dhabi Global Market (ADGM)
Other jurisdictions where transfers occur (Article 27 transfers, with safeguards):
- United Arab Emirates (mainland) — UAE PDPL framework; performance of contract / regulatory compliance
- Kingdom of Saudi Arabia, Jordan, Sultanate of Oman, Bahrain, Qatar (mainland) — GCC counterparties; respective national data protection frameworks
- Kuwait — sectoral data protection framework
For transfers to non-adequate jurisdictions, we rely on: Standard Contractual Clauses (Article 27(2)(c)) as the primary mechanism; performance of a contract with the data subject (Article 27(3)(b)) where applicable; and compliance with applicable laws or international obligations (Article 27(3)(i)) where required.
2.11Your Rights Under DIFC DPL
Subject to applicable conditions and exceptions under DIFC DPL, you have the following rights regarding your personal data:
- Right of access (Art. 32) — to obtain confirmation of whether we process your personal data and, if so, a copy of that data and certain information about the processing.
- Right to rectification (Art. 33) — to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure (Art. 34) — to have personal data deleted in certain circumstances (also known as the “right to be forgotten”).
- Right to restriction (Art. 35) — to restrict our processing of your personal data in certain circumstances.
- Right to data portability (Art. 38) — to receive personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object (Art. 36) — to object to processing based on legitimate interests, including for direct marketing purposes (which always succeeds).
- Right not to be subject to automated decision-making (Art. 39) — to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
- Right to withdraw consent — to withdraw consent at any time, without affecting the lawfulness of prior processing.
- Right to lodge a complaint — with the DIFC Commissioner of Data Protection.
To exercise these rights, contact us by email at dataprotection@raseenlabs.com. We will respond within one (1) month, extendable by a further two (2) months for complex requests, as provided by DIFC DPL Article 31.
You also have the right to lodge a complaint with the Commissioner of Data Protection in the DIFC at any time:
DIFC Commissioner of Data Protection
Email: commissioner@dp.difc.ae
Website: https://www.dp.difc.ae
2.13Children's Privacy
The Software and Website are not intended for individuals under the age of sixteen (16). We do not knowingly collect personal data from children below that age.
If we become aware that we have collected personal data from a child below the applicable age, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, contact us at privacy@raseenlabs.com.
2.14Third-Party Services and Links
The Website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with any personal data.
2.15Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- posting the updated Privacy Policy on this page;
- updating the “Last Updated” date at the top;
- where required by law or appropriate to the change, sending you a direct notice (email or in-Software notification).
Continued use of the Software or Website after the effective date of the updated Privacy Policy constitutes acceptance.
2.16Contact Us and Data Protection Officer
General privacy inquiries:
dataprotection@raseenlabs.com
Data Protection Officer (DPO). Raseen Labs has not appointed a formal Data Protection Officer under DIFC DPL Article 16. As declared in the Article 14 notification filed with the DIFC Commissioner, Raseen Labs's processing activities do not constitute High Risk Processing under Schedule 1, Article 3 of the DIFC DPL: processing comprises modest-volume website visitor data, customer account records, and opt-in telemetry; no special categories of personal data, no children's data, and no regular or systematic monitoring of data subjects. A Data Protection Contact has been appointed for Commissioner correspondence and data subject inquiries.
Mailing address:
Premises IH-00-01-03-OF-05, Level 3, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates